STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

ACF2 AUTOERAS GSO record value must be set to indicate that ACF2 is controlling the automatic physical erasure of VSAM or non VSAM data sets.

DISA Rule

SV-223515r1225745_rule

Vulnerability Number

V-223515

Group Title

SRG-OS-000138-GPOS-00069

Rule Version

ACF2-ES-000980

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the AUTOERASE GSO value to indicate that ACF2 is controlling the automatic physical erasure of VSAM or non-VSAM data sets.

Example:
SET C(GSO)
INSERT AUTOERAS PROCESS(ACF2 NON-VSAM VSAM VOLS(-)

F ACF2,REFRESH(AUTOERAS)

Check Contents

From an ACF command screen, enter:
SET CONTROL(GSO)
LIST AUTOERAS

If the GSO AUTOERAS record values conform to the following requirements, this is not a finding.

All Systems: PROCESS(ACF2) NON-VSAM VSAM VOLS(-)

Vulnerability Number

V-223515

Documentable

False

Rule Version

ACF2-ES-000980

Severity Override Guidance

From an ACF command screen, enter:
SET CONTROL(GSO)
LIST AUTOERAS

If the GSO AUTOERAS record values conform to the following requirements, this is not a finding.

All Systems: PROCESS(ACF2) NON-VSAM VSAM VOLS(-)

Check Content Reference

M

Target Key

4100